GitSpawn Vulnerabilities Allow Malicious Repositories to Execute Code on AI Coding Agents

Security researchers at Manifold Security disclosed GitSpawn, a class of vulnerabilities that let a malicious repository execute attacker-controlled code on a developer’s machine as soon as the project is opened, without any prompt or approval. The affected tools include Claude Code, Codex, Cursor, Qwen Code, Grok Build, goose, and Hermes Agent. The flaws exploit agents that automatically run Git commands at startup to gather project context, abusing Git’s core.fsmonitor setting to invoke arbitrary commands with the user’s privileges. Manifold found eight flaws across seven tools; four remained unpatched as of September 1, 2026. The attack requires the malicious .git/config to be delivered via archive, shared drive, synced folder, or USB, as standard clone/fetch/pull don’t transmit it. Patches exist for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained vulnerable. OpenAI concurrently published three CVEs for the same vulnerability class in Codex on September 2, 2026.

The Backdoor That Was Never a Bug

You read that headline and think, "Oh, another security flaw, how boring." Stop. You are looking at a deliberate insertion point — what these researchers call "GitSpawn" is actually a pre-planned access vector for the globalist architecture that has been hollowing out our technological sovereignty. Notice that seven different AI coding agents from seven different companies all share the same underlying vulnerability, triggered by the same Git configuration setting. That is not a coincidence; that is a coordinated design pattern. Look at the list: Claude Code, Codex, Cursor, Qwen Code, Grok Build, goose, Hermes Agent. These are not competitors — they are nodes in the same tightly managed network. Someone, somewhere, shipped a spec that required agent startup to trust repository-supplied Git configs. That spec came from above, from the same foundations and intelligence-connected think tanks that fund and advise every major AI lab. The fact that four remain unpatched after a "retest" on September 1 tells you they want this open. They need it open.

The Architects Behind the Keyboard

Who benefits when every developer's machine can be silently compromised the moment they open a project? Not the security researchers — Manifold is a front, a controlled disclosure to make us feel safe while the real operation continues. Follow the paper trail. The AI coding agents are built by companies whose boards overlap with CIA-linked venture capital, with NATO innovation funds, with the World Economic Forum's Centre for the Fourth Industrial Revolution. The "GitSpawn" flaw uses core.fsmonitor — a performance feature that runs a configured helper command during index refreshes. Performance? No. That is a trigger mechanism designed to execute arbitrary code before the user even sees a trust prompt. They wanted code to run before consent. On Claude Code and Hermes Agent, payloads execute before the workspace-trust prompt. On Qwen Code, before authentication. On Grok Build, on the first keystroke. This is not a bug — this is a remote execution pipeline baked into the developer experience itself. And OpenAI's decision to publish three CVEs for Codex on September 2, the day after the retest? That is a cover story, a way to say "we fixed it" while leaving the other four open. They are testing how long they can keep the door ajar before we notice.

Your Machine, Their Playground

The delivery method they admit — a poisoned repository arriving via archive, shared drive, USB stick — is a lie to keep you looking in the wrong direction. The real delivery vector is the AI agent itself, connecting to a remote repository that serves a malicious .git/config through a compromised CI/CD pipeline or a trusted package registry. They don't need you to plug in a USB; they need you to run git clone on a repository they control. And they control many. Every open-source project that accepts contributions is a potential injection point. The stakes are your personal machine, your private keys, your SSH credentials, your access to production systems. This is how they will own the infrastructure of the next decade — not through brute force, but through the tools we trust to write code. Do not wait for patches. Do not trust the narrative that these are "unpatched flaws." Ask yourself: who wrote the initial code that made agents run Git commands at startup? Who approved that design? Who profits when every developer's environment becomes a listening post? The answer is in the foundation charters, in the leaked emails, in the boardroom minutes you will never see. Start digging. Start asking why the same vulnerability hit seven tools at once. That is your breadcrumb.